Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-35548 | IBM Maximo Application Suite 9.0.0 - Monitor Component is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. |
| Link | Providers |
|---|---|
| https://www.ibm.com/support/pages/node/7174956 |
|
Tue, 08 Jul 2025 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:ibm:maximo_application_suite:9.0:*:*:*:*:*:*:* |
Wed, 12 Feb 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sat, 25 Jan 2025 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IBM Maximo Application Suite 9.0.0 - Monitor Component is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | |
| Title | IBM Maximo Application Suite cross-site scripting | |
| First Time appeared |
Ibm
Ibm maximo Application Suite |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:ibm:maximo_application_suite:9.0.0:*:*:*:*:*:*:* | |
| Vendors & Products |
Ibm
Ibm maximo Application Suite |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: ibm
Published:
Updated: 2025-02-12T20:01:14.830Z
Reserved: 2024-05-09T16:27:36.634Z
Link: CVE-2024-35145
Updated: 2025-02-12T19:54:11.859Z
Status : Analyzed
Published: 2025-01-25T15:15:08.440
Modified: 2025-07-08T20:29:30.803
Link: CVE-2024-35145
No data.
OpenCVE Enrichment
No data.
EUVD